In the evaluation of https://github.com/sysrepo/sysrepo/pull/3353, CodeQL seems to think there is uncontrolled data used in path expression, when there is none. `This argument to a file access function is derived from and then passed to op_export(file_path), which calls fopen(__filename).` https://github.com/sysrepo/sysrepo/pull/3353/files `step_create_input_file` is the function responsible to create a unique filename, and is untouched in this diff, and it seems to be not exploitable. https://github.com/sysrepo/sysrepo/pull/3353/checks?check_run_id=27465095770